CA DevTest Clickjacking Vulnerability

Document ID : KB000074800
Last Modified Date : 05/04/2018
Show Technical Document Details
Issue:
Port 1505 Web Application Potentially Vulnerable to Clickjacking

The remote web server may fail to mitigate a class of web application The remote web server does not set an X-Frame-Options response header or a Content-Security-Policy 'frame-ancestors' response header in all content responses. This could potentially expose the site to a clickjacking or UI redress attack, in which an attacker can trick a user into clicking an area of the vulnerable page that is different than what the user perceives the page to be. This can result in a user performing fraudulent or malicious transactions.

X-Frame-Options has been proposed by Microsoft as a way to mitigate clickjacking attacks and is currently supported by all major browser vendors.

Content-Security-Policy (CSP) has been proposed by the W3C Web Application Security Working Group, with increasing support among all major browser vendors, as a way to mitigate clickjacking and other attacks. The 'frame-ancestors' policy directive restricts which sources can embed the protected resource. Note that while the X-Frame-Options and Content-Security-Policy response headers are not the only mitigations for clickjacking, they are currently the most reliable methods that can be detected through automation. Therefore, this plugin may produce false positives if other mitigation strategies (e.g., frame-busting JavaScript) are deployed or if the page does not perform any security-sensitive transactions. Return the X-Frame-Options or Content-Security-Policy (with the 'frame-ancestors' directive) HTTP header with the page's response. This prevents the page's content from being rendered by another site when using the frame or iframe HTML tags.

""https://www.tenable.com/plugins/nessus/85582"" ""https://www.symantec.com/connect/forums/web-application-potentially-vulnerable-clickjacking""

CVE - CVE-2016-0734

Description. The web-based administration console in Apache ActiveMQ 5.x before 5.13.2 does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) FRAME or (2) IFRAME element. References. Note: References are ... www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0734
Environment:
DevTest 10.1.0, can also happen in other DevTest version.
Resolution:
Please open a new support case to get the fix for this vulnerability.

Refer to defect DE352026.